CVE-2024-12731

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 9, 2025

Summary

CVE-2024-12731 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Aklamator INfeed WordPress plugin before version 2.0.0. The issue stems from the plugin's failure to sanitize and escape a user input parameter before rendering it on the page. An attacker could exploit this flaw by injecting malicious scripts into the parameter, which would be executed in the context of the page visited by the high-privilege user, such as an admin, resulting in potential unauthorized access or data theft.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share